June 2016
Beginner to intermediate
322 pages
6h 18m
English
Let's take a look at Plaso architecture. Plaso has a few core components which perform independent roles:
Let's look at them in more detail.
At this stage, some preprocessing tasks should be done prior to all other processing. For example, before mounting the image and determining which OS is installed on the disk, collect some information which will be used in the next stage.
The preprocessing process should collect the following:
In the collection stage, the process goes over the image, directory, or mount point, and finds ...